← WordPress Vulnerabilities
WordPress security by component

AR for WooCommerce

AR for WooCommerce is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 03, 2026; the highest published CVSS base score is 10.

Plugin slug: ar-for-woocommerce

CVE-2026-14352: AR for WooCommerce: Filesystem traversal

AR for WooCommerce is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 8.40.

PublishedJul 03, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for ar-for-woocommerce
Safe version
Jul 03, 2026 CVE-2026-14352
AR for WooCommerce: Filesystem traversal
AR for WooCommerce is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 8.40.
See mitigation notes
CVE7.5
NVDPending
Oct 30, 2024 CVE-2024-50510
AR For Woocommerce: Dangerous file upload
AR For Woocommerce is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE10.0
NVDPending